<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Vundo] Ran all spyware software.. still have Vundo.. in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20566030</link>
<description></description>
<language>en</language>
<pubDate>Mon, 30 Nov 2009 15:24:52 EDT</pubDate>
<lastBuildDate>Mon, 30 Nov 2009 15:24:52 EDT</lastBuildDate>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20573955</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : Ok got it! Everything seems back to normal! Thanks!<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20573955</guid>
<pubDate>Sun, 01 Jun 2008 18:10:57 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20571888</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Click Start, and enter "system" into the Search bar and press Enter.  In the menu that opens, click on "System Protect" in the left hand menu.<br><br>Note the checked boxes.  We will need to recheck them later.<br>Now uncheck all the checked boxes at this menu:<br> <IMG SRC="http://www.howtogeek.com/wp-content/uploads/2007/01/WindowsLiveWriter/DisableSystemRestoreinWindowsVista_133FB/image%7B0%7D%5B1%5D.png"> <br><br>Click to "Turn System Restore Off" when you see this Prompt:<br> <IMG SRC="http://www.howtogeek.com/wp-content/uploads/2007/01/WindowsLiveWriter/DisableSystemRestoreinWindowsVista_133FB/image%7B0%7D%5B2%5D.png"> <br><br>This removes older infected System Restore Points.  We can now re-enable System Restore on your clean system.  Repeat the steps, but this time <b>restore</b> the checkmark(s)to the drives to re-enable System Restore.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20571888</guid>
<pubDate>Sun, 01 Jun 2008 07:16:22 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20571706</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : I followed all of the instructions except the new restore point..I couldnt get it to work by right clicking on My computer.. but I took a new HJT.. hows it look..<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 2:51:27 PM, on 5/31/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\system32\taskeng.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br>C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe<br>C:\Program Files\WinTidy\WinTidy.exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"<br>O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe<br>O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe<br>O4 - Global Startup: hpzrcv01.LNK = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br>O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)<br>O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe<br><br>--<br>End of file - 7132 bytes<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20571706</guid>
<pubDate>Sun, 01 Jun 2008 03:53:32 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20571146</link>
<description><![CDATA[<A HREF="/useremail/u/1554845"><b>shiftergreen</b></A> : Well, I think we are back to what passes for normal. I realize that you and the folks that staff this website do so as a public service. Please accept sincere thanks for your willingness to be there and to help rescue people like me who have been electronically invaded by the bad guys. I hope that I will not need to trouble you again but is a comfort to know that you are available if evil prevails.<br><br>THANKS!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20571146</guid>
<pubDate>Sat, 31 May 2008 23:31:21 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20568108</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Do yourself a big favor and remove TeaTimer, part of SpyBot, from your startup.  The protection of TeaTimer is simply better handled under Vista with Windows Defender, which also does quite a bit more.  See my first reply for instructions on disabling TeaTimer, as it still shows as active on your system -- you want this SpyBot feature gone, not just disabled.<br><br>Then, Open HijackThis and "fix" these entries (if they still exist):<br><br><b>O2 - BHO: (no name) - {2b7a6b19-a1d8-4366-8ae7-5157893bb823} - (no file)<br>O2 - BHO: (no name) - {C1349062-D1A1-40DB-83CD-68CADE84FC37} - (no file)<br>O4 - HKLM\..\Run: [MSServer] "rundll32.exe" C:\Windows\system32\yayaXOFY.dll,#1</b><br><br>I believe we are finished.<br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Please download <b>OTMoveIt2</b> by OldTimer to your Desktop (only):<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>&#8226; Please double-click OTMoveIt.exe to run it.<br>&#8226; Click on the green <b>CleanUp!</b> button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. <br>&#8226; After the list has been download you'll be asked if you want to Begin cleanup process? Select "Yes".<br>&#8226; This step removes the files, folders, and shortcuts created by the tools I had you download and run.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20568108</guid>
<pubDate>Sat, 31 May 2008 09:40:01 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20567380</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : K that worked.. here ya go..<br><br>ComboFix 08-05-29.1 - Bry4n 2008-05-30 12:04:36.3 - NTFSx86<br>Microsoft&reg; Windows Vista&#153; Home Premium   6.0.6000.0.1252.1.1033.18.1336 [GMT -5:00]<br>Running from: C:\Users\Bry4n\Desktop\ComboFix.exe<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Windows\system32\AutoRun.inf<br>C:\Windows\System32\effhPqss.ini<br>C:\Windows\System32\effhPqss.ini2<br>C:\Windows\system32\hqfluscd.ini<br>C:\Windows\System32\kTvCcLTv.ini<br>C:\Windows\System32\kTvCcLTv.ini2<br>C:\Windows\system32\mcrh.tmp<br>C:\Windows\System32\ocklxenh.ini<br>C:\Windows\system32\qgmewliy.ini<br>C:\Windows\system32\sfkwipus.dll<br>J:\Autorun.inf<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-04-28 to 2008-05-30  )))))))))))))))))))))))))))))))<br>.<br><br>2008-05-30 20:47 . 2008-05-30 20:47&#9;&#9;d--------&#9;C:\Users\Bry4n\AppData\Roaming\Malwarebytes<br>2008-05-30 20:47 . 2008-05-30 20:47&#9;&#9;d--------&#9;C:\Users\All Users\Malwarebytes<br>2008-05-30 20:47 . 2008-05-30 20:47&#9;&#9;d--------&#9;C:\ProgramData\Malwarebytes<br>2008-05-30 20:47 . 2008-05-30 20:47&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-05-30 20:47 . 2008-05-30 01:06&#9;34,296&#9;--a------&#9;C:\Windows\System32\drivers\mbamcatchme.sys<br>2008-05-30 20:47 . 2008-05-30 01:06&#9;15,864&#9;--a------&#9;C:\Windows\System32\drivers\mbam.sys<br>2008-05-30 20:45 . 2008-05-30 20:45&#9;&#9;d--------&#9;C:\Users\All Users\Hewlett-Packard<br>2008-05-30 20:45 . 2008-05-30 20:45&#9;&#9;d--------&#9;C:\ProgramData\Hewlett-Packard<br>2008-05-30 20:37 . 2007-03-28 14:01&#9;118,272&#9;--a------&#9;C:\Windows\System32\hpz3l5ha.dll<br>2008-05-30 20:35 . 2008-05-30 20:35&#9;&#9;d--------&#9;C:\Program Files\HP<br>2008-05-30 20:33 . 2008-05-30 20:33&#9;&#9;d--------&#9;C:\Users\All Users\HP<br>2008-05-30 20:33 . 2008-05-30 20:33&#9;&#9;d--------&#9;C:\ProgramData\HP<br>2008-05-30 20:33 . 2007-03-17 15:39&#9;958,464&#9;--a------&#9;C:\Windows\System32\hpotiop4.dll<br>2008-05-30 20:33 . 2007-03-17 15:39&#9;675,840&#9;--a------&#9;C:\Windows\System32\hpowiax4.dll<br>2008-05-30 20:33 . 2007-03-08 14:20&#9;364,544&#9;--a------&#9;C:\Windows\System32\hppldcoi.dll<br>2008-05-30 20:33 . 2007-03-08 14:20&#9;309,760&#9;--a------&#9;C:\Windows\System32\difxapi.dll<br>2008-05-30 20:33 . 2007-03-17 15:39&#9;303,104&#9;--a------&#9;C:\Windows\System32\hpovst11.dll<br>2008-05-30 20:33 . 2007-03-31 00:29&#9;267,864&#9;--a------&#9;C:\Windows\System32\hpzids01.dll<br>2008-05-30 20:33 . 2008-05-30 20:35&#9;121,273&#9;--a------&#9;C:\Windows\hpoins15.dat<br>2008-05-30 20:33 . 2007-09-21 10:15&#9;1,037&#9;---------&#9;C:\Windows\hpomdl15.dat<br>2008-05-30 19:20 . 2008-05-30 19:20&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-05-30 17:24 . 2008-05-30 17:24&#9;&#9;d--------&#9;C:\Windows\Sun<br>2008-05-30 17:03 . 2008-05-30 23:21&#9;&#9;d-a------&#9;C:\Users\All Users\TEMP<br>2008-05-30 17:03 . 2008-05-30 23:21&#9;&#9;d-a------&#9;C:\ProgramData\TEMP<br>2008-05-30 17:02 . 2007-12-10 14:53&#9;81,288&#9;--a------&#9;C:\Windows\System32\drivers\iksyssec.sys<br>2008-05-30 17:02 . 2007-12-10 14:53&#9;66,952&#9;--a------&#9;C:\Windows\System32\drivers\iksysflt.sys<br>2008-05-30 17:02 . 2008-02-01 12:55&#9;42,376&#9;--a------&#9;C:\Windows\System32\drivers\ikfilesec.sys<br>2008-05-30 17:02 . 2007-12-10 14:53&#9;29,576&#9;--a------&#9;C:\Windows\System32\drivers\kcom.sys<br>2008-05-30 17:01 . 2008-05-30 17:01&#9;&#9;d--------&#9;C:\Users\Bry4n\AppData\Roaming\PC Tools<br>2008-05-30 17:01 . 2008-05-30 23:28&#9;&#9;d--------&#9;C:\Program Files\Spyware Doctor<br>2008-05-30 16:59 . 2008-05-30 17:04&#9;&#9;d--------&#9;C:\Program Files\Java<br>2008-05-30 16:59 . 2008-05-30 16:59&#9;&#9;d--------&#9;C:\Program Files\Common Files\Java<br>2008-05-30 16:09 . 2008-05-30 16:09&#9;&#9;d--------&#9;C:\Program Files\MSXML 4.0<br>2008-05-30 16:09 . 2008-05-30 16:12&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-05-30 14:40 . 2008-05-30 16:04&#9;153&#9;--a------&#9;C:\Windows\wininit.ini<br>2008-05-30 14:07 . 2008-05-30 14:07&#9;24,576&#9;--a------&#9;C:\Windows\System32\VundoFixSVC.exe<br>2008-05-30 13:27 . 2008-05-30 18:01&#9;&#9;d--------&#9;C:\VundoFix Backups<br>2008-05-30 12:45 . 2008-05-30 12:47&#9;&#9;d--------&#9;C:\Users\All Users\Spybot - Search & Destroy<br>2008-05-30 12:45 . 2008-05-30 12:47&#9;&#9;d--------&#9;C:\ProgramData\Spybot - Search & Destroy<br>2008-05-30 12:45 . 2008-05-30 12:45&#9;&#9;d--------&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-05-29 08:14 . 2008-05-29 08:14&#9;0&#9;--ah-----&#9;C:\Users\Default.LOG2<br>2008-05-29 08:14 . 2008-05-29 08:14&#9;0&#9;--ah-----&#9;C:\Users\Default.LOG1<br>2008-05-29 08:14 . 2008-05-29 08:14&#9;0&#9;--ah-----&#9;C:\ProgramData.LOG2<br>2008-05-29 08:14 . 2008-05-29 08:14&#9;0&#9;--ah-----&#9;C:\ProgramData.LOG1<br>2008-05-29 02:14 . 2008-05-30 20:25&#9;2,375&#9;--a------&#9;C:\rollback.ini<br>2008-05-29 01:25 . 2008-05-29 01:25&#9;&#9;d--------&#9;C:\Users\All Users\CheckPoint<br>2008-05-29 01:25 . 2008-05-29 01:25&#9;&#9;d--------&#9;C:\ProgramData\CheckPoint<br>2008-05-29 01:25 . 2008-01-09 03:32&#9;276,368&#9;--a------&#9;C:\Windows\System32\drivers\~GLH0014.TMP<br>2008-05-29 00:46 . 2008-05-30 11:56&#9;&#9;d--------&#9;C:\Windows\Internet Logs<br>2008-05-29 00:30 . 2008-05-29 00:31&#9;&#9;d--------&#9;C:\Users\Bry4n\AppData\Roaming\MalwareRemovalBot<br>2008-05-28 22:08 . 2008-05-28 22:18&#9;&#9;d--------&#9;C:\Users\All Users\Lavasoft<br>2008-05-28 22:08 . 2008-05-28 22:18&#9;&#9;d--------&#9;C:\ProgramData\Lavasoft<br>2008-05-28 22:08 . 2008-05-28 22:08&#9;&#9;d--------&#9;C:\Program Files\Lavasoft<br>2008-05-28 22:07 . 2008-05-28 22:07&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-05-28 20:22 . 2008-05-28 20:22&#9;&#9;d--------&#9;C:\Users\All Users\Hagel Technologies<br>2008-05-28 20:22 . 2008-05-28 20:22&#9;&#9;d--------&#9;C:\ProgramData\Hagel Technologies<br>2008-05-28 20:22 . 2008-05-28 20:22&#9;&#9;d--------&#9;C:\Program Files\DU Meter<br>2008-05-28 20:17 . 2008-05-30 11:53&#9;69&#9;--a------&#9;C:\Windows\NeroDigital.ini<br>2008-05-28 20:14 . 2008-05-28 20:14&#9;&#9;d--------&#9;C:\Windows\WinAVI Video Converter 9.0<br>2008-05-28 20:14 . 2008-05-28 20:14&#9;&#9;d--------&#9;C:\Program Files\WinAVI Video Converter 9.0<br>2008-05-28 20:08 . 2006-10-26 19:56&#9;32,592&#9;--a------&#9;C:\Windows\System32\msonpmon.dll<br>2008-05-28 20:05 . 2008-05-28 20:05&#9;&#9;d--------&#9;C:\Program Files\Microsoft Works<br>2008-05-28 20:01 . 2008-05-28 20:01&#9;&#9;d--------&#9;C:\Windows\PCHEALTH<br>2008-05-28 20:01 . 2008-05-28 20:01&#9;&#9;d--------&#9;C:\Program Files\Microsoft.NET<br>2008-05-28 19:58 . 2008-05-28 19:58&#9;&#9;d--------&#9;C:\Program Files\Microsoft Visual Studio 8<br>2008-05-28 19:57 . 2008-05-28 20:10&#9;&#9;d--------&#9;C:\Users\All Users\Microsoft Help<br>2008-05-28 19:57 . 2008-05-28 20:10&#9;&#9;d--------&#9;C:\ProgramData\Microsoft Help<br>2008-05-28 19:48 . 2008-05-28 19:54&#9;&#9;d--------&#9;C:\Users\Bry4n\AppData\Roaming\Ahead<br>2008-05-28 19:45 . 2008-05-28 19:45&#9;&#9;d--------&#9;C:\Users\All Users\Nero<br>2008-05-28 19:45 . 2008-05-28 19:45&#9;&#9;d--------&#9;C:\ProgramData\Nero<br>2008-05-28 19:45 . 2008-05-28 19:45&#9;&#9;d--------&#9;C:\Program Files\Nero<br>2008-05-28 19:45 . 2008-05-28 19:47&#9;&#9;d--------&#9;C:\Program Files\Common Files\Ahead<br>2008-05-28 19:33 . 2008-05-28 19:33&#9;&#9;d--------&#9;C:\Users\All Users\Adobe Systems<br>2008-05-28 19:33 . 2008-05-28 19:33&#9;&#9;d--------&#9;C:\ProgramData\Adobe Systems<br>2008-05-28 19:27 . 2008-05-28 19:27&#9;&#9;d--------&#9;C:\Program Files\Common Files\Adobe Systems Shared<br>2008-05-28 19:24 . 2008-05-28 19:24&#9;&#9;d--------&#9;C:\Users\All Users\Adobe<br>2008-05-28 19:24 . 2008-05-28 19:27&#9;&#9;d--------&#9;C:\Program Files\Common Files\Adobe<br>2008-05-28 19:20 . 2008-05-30 19:15&#9;&#9;d--------&#9;C:\Users\Bry4n\AppData\Roaming\iPhoneRingToneMaker<br>2008-05-28 19:20 . 2008-05-28 19:20&#9;&#9;d--------&#9;C:\Program Files\iPhoneRingToneMaker<br>2008-05-28 19:11 . 2008-05-28 19:11&#9;&#9;d--------&#9;C:\Windows\System32\Macromed<br>2008-05-28 19:11 . 2008-05-28 19:11&#9;1,160&#9;--a------&#9;C:\Windows\mozver.dat<br>2008-05-28 19:04 . 2008-05-28 20:13&#9;&#9;d--------&#9;C:\Program Files\Microsoft Money 2007<br>2008-05-28 07:54 . 2008-05-30 11:52&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-05-28 07:54 . 2008-05-30 11:56&#9;&#9;d--------&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-05-28 07:26 . 2008-05-30 11:56&#9;&#9;d--------&#9;C:\Users\All Users\Symantec<br>2008-05-28 07:26 . 2008-05-30 11:56&#9;&#9;d--------&#9;C:\ProgramData\Symantec<br>2008-05-28 07:16 . 2008-05-30 12:09&#9;54,156&#9;--ah-----&#9;C:\Windows\QTFont.qfn<br>2008-05-28 07:16 . 2008-05-28 07:16&#9;1,409&#9;--a------&#9;C:\Windows\QTFont.for<br>2008-05-28 04:09 . 2008-05-28 04:09&#9;694,784&#9;--a------&#9;C:\Windows\System32\localspl.dll<br>2008-05-28 04:08 . 2008-05-28 04:08&#9;2,923,520&#9;--a------&#9;C:\Windows\explorer.exe<br>2008-05-28 04:07 . 2008-05-28 04:07&#9;194,560&#9;--a------&#9;C:\Windows\System32\WebClnt.dll<br>2008-05-28 04:07 . 2008-05-28 04:07&#9;110,080&#9;--a------&#9;C:\Windows\System32\drivers\mrxdav.sys<br>2008-05-28 04:05 . 2008-05-28 04:05&#9;376,320&#9;--a------&#9;C:\Windows\System32\winsrv.dll<br>2008-05-28 04:05 . 2008-05-28 04:05&#9;49,664&#9;--a------&#9;C:\Windows\System32\csrsrv.dll<br>2008-05-28 04:03 . 2008-05-28 04:03&#9;1,060,920&#9;--a------&#9;C:\Windows\System32\drivers\ntfs.sys<br>2008-05-28 04:03 . 2008-05-28 04:03&#9;41,984&#9;--a------&#9;C:\Windows\System32\drivers\monitor.sys<br>2008-05-28 04:01 . 2008-05-28 04:01&#9;374,456&#9;--a------&#9;C:\Windows\System32\mcupdate_GenuineIntel.dll<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;8,147,968&#9;--a------&#9;C:\Windows\System32\wmploc.DLL<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;414,208&#9;--a------&#9;C:\Windows\System32\msscp.dll<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;356,864&#9;--a------&#9;C:\Windows\System32\MediaMetadataHandler.dll<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;7,680&#9;--a------&#9;C:\Windows\System32\spwmp.dll<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;4,096&#9;--a------&#9;C:\Windows\System32\msdxm.ocx<br>2008-05-28 04:00 . 2008-05-28 04:00&#9;4,096&#9;--a------&#9;C:\Windows\System32\dxmasf.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;396,800&#9;--a------&#9;C:\Windows\System32\MPSSVC.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;392,192&#9;--a------&#9;C:\Windows\System32\FirewallAPI.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;178,688&#9;--a------&#9;C:\Windows\System32\iphlpsvc.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;86,016&#9;--a------&#9;C:\Windows\System32\icfupgd.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;63,488&#9;--a------&#9;C:\Windows\System32\drivers\mpsdrv.sys<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;61,952&#9;--a------&#9;C:\Windows\System32\cmifw.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;23,040&#9;--a------&#9;C:\Windows\System32\drivers\tunnel.sys<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;16,896&#9;--a------&#9;C:\Windows\System32\wfapigp.dll<br>2008-05-28 03:59 . 2008-05-28 03:59&#9;15,360&#9;--a------&#9;C:\Windows\System32\drivers\TUNMP.SYS<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;3,504,696&#9;--a------&#9;C:\Windows\System32\ntkrnlpa.exe<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;3,470,392&#9;--a------&#9;C:\Windows\System32\ntoskrnl.exe<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;211,000&#9;--a------&#9;C:\Windows\System32\drivers\volsnap.sys<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;154,624&#9;--a------&#9;C:\Windows\System32\drivers\nwifi.sys<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;109,624&#9;--a------&#9;C:\Windows\System32\drivers\ataport.sys<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;45,112&#9;--a------&#9;C:\Windows\System32\drivers\pciidex.sys<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;21,560&#9;--a------&#9;C:\Windows\System32\drivers\atapi.sys<br>2008-05-28 03:57 . 2008-05-28 03:57&#9;17,464&#9;--a------&#9;C:\Windows\System32\drivers\intelide.sys<br>2008-05-28 03:56 . 2008-05-28 03:56&#9;104,448&#9;--a------&#9;C:\Windows\System32\DWWIN.EXE<br>2008-05-28 03:55 . 2008-05-28 03:55&#9;1,191,936&#9;--a------&#9;C:\Windows\System32\msxml3.dll<br>2008-05-28 03:55 . 2008-05-28 03:55&#9;224,768&#9;--a------&#9;C:\Windows\System32\drivers\usbport.sys<br>2008-05-28 03:55 . 2008-05-28 03:55&#9;192,000&#9;--a------&#9;C:\Windows\System32\drivers\usbhub.sys<br>2008-05-28 03:55 . 2008-05-28 03:55&#9;73,216&#9;--a------&#9;C:\Windows\System32\drivers\usbccgp.sys<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-05-29 01:05&#9;---------&#9;d-----w&#9;C:\Program Files\MSBuild<br>2008-05-28 12:14&#9;174&#9;--sha-w&#9;C:\Program Files\desktop.ini<br>2008-05-28 12:08&#9;---------&#9;d-----w&#9;C:\Program Files\Windows Sidebar<br>2008-05-28 12:08&#9;---------&#9;d-----w&#9;C:\Program Files\Windows Mail<br>2008-05-28 12:08&#9;---------&#9;d-----w&#9;C:\Program Files\Windows Defender<br>2008-05-28 12:08&#9;---------&#9;d-----w&#9;C:\Program Files\Windows Calendar<br>2008-05-28 09:10&#9;61,952&#9;----a-w&#9;C:\Windows\system32\drivers\wanarp.sys<br>2008-05-28 09:10&#9;48,640&#9;----a-w&#9;C:\Windows\system32\drivers\ndproxy.sys<br>2008-05-28 09:10&#9;20,480&#9;----a-w&#9;C:\Windows\system32\drivers\ndistapi.sys<br>2008-05-28 09:09&#9;70,144&#9;----a-w&#9;C:\Windows\system32\drivers\pacer.sys<br>2008-05-28 09:09&#9;619,008&#9;----a-w&#9;C:\Windows\system32\drivers\dxgkrnl.sys<br>2008-05-28 09:08&#9;28,344&#9;----a-w&#9;C:\Windows\system32\drivers\battc.sys<br>2008-05-28 09:08&#9;258,232&#9;----a-w&#9;C:\Windows\system32\drivers\acpi.sys<br>2008-05-28 09:08&#9;20,920&#9;----a-w&#9;C:\Windows\system32\drivers\compbatt.sys<br>2008-05-28 09:08&#9;14,208&#9;----a-w&#9;C:\Windows\system32\drivers\CmBatt.sys<br>2008-05-28 08:48&#9;54,784&#9;----a-w&#9;C:\Windows\system32\drivers\i8042prt.sys<br>2008-05-28 08:48&#9;495,160&#9;----a-w&#9;C:\Windows\system32\drivers\Wdf01000.sys<br>2008-05-28 08:48&#9;35,384&#9;----a-w&#9;C:\Windows\system32\drivers\WdfLdr.sys<br>2008-05-28 08:48&#9;35,384&#9;----a-w&#9;C:\Windows\system32\drivers\kbdclass.sys<br>2008-05-28 08:48&#9;34,360&#9;----a-w&#9;C:\Windows\system32\drivers\mouclass.sys<br>2008-05-28 08:48&#9;19,968&#9;----a-w&#9;C:\Windows\system32\drivers\sermouse.sys<br>2008-05-28 08:48&#9;15,872&#9;----a-w&#9;C:\Windows\system32\drivers\mouhid.sys<br>2008-05-28 08:36&#9;537,600&#9;----a-w&#9;C:\Windows\AppPatch\AcLayers.dll<br>2008-05-28 08:36&#9;449,536&#9;----a-w&#9;C:\Windows\AppPatch\AcSpecfc.dll<br>2008-05-28 08:36&#9;2,560&#9;----a-w&#9;C:\Windows\AppPatch\AcRes.dll<br>2008-05-28 08:36&#9;2,144,256&#9;----a-w&#9;C:\Windows\AppPatch\AcGenral.dll<br>2008-05-28 08:36&#9;173,056&#9;----a-w&#9;C:\Windows\AppPatch\AcXtrnal.dll<br>2008-05-28 08:32&#9;52,736&#9;----a-w&#9;C:\Windows\AppPatch\iebrshim.dll<br>.<br><br>------- Sigcheck -------<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2b7a6b19-a1d8-4366-8ae7-5157893bb823}]<br><br>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1349062-D1A1-40DB-83CD-68CADE84FC37}]<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49 153136]<br>"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2007-10-15 15:19 2582288]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [ ]<br>"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48 479232]<br>"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2008-05-28 01:18 454144]<br>"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]<br>"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]<br>"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53 153136]<br>"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]<br>"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]<br>"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]<br>"MSServer"="rundll32.exe" [2006-11-02 04:45 44544 C:\Windows\System32\rundll32.exe]<br>"MSConfig"="C:\Windows\System32\msconfig.exe" [2006-11-02 04:45 222208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]<br>"@"="" []<br><br>C:\Users\Bry4n\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\<br>Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]<br>iPhoneRingToneMaker.lnk - C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe [2008-05-28 19:20:53 1138176]<br>WinTidy.lnk - C:\Program Files\WinTidy\WinTidy.exe [2001-10-08 06:14:20 585216]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]<br>"EnableLUA"= 0 (0x0)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]<br>"TCP Query User{63D1F38F-4644-4620-87F7-A0DC6BA5719A}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus<br>"UDP Query User{36FC0908-280A-4B25-9579-F77E627046A5}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus<br>"{87452224-DA98-47B7-9B1C-8E1090213B8F}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour<br>"{A98384FF-001A-4DFA-8089-8675BA00B784}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour<br>"{2369248E-F421-472A-A8D3-758B714E6A3D}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{1A17C05F-6E59-4BA0-8D8B-94A721372DE5}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes<br>"{B799F487-7BE5-45CC-9A7F-CADD9664F256}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook<br>"{6F1AE458-6338-4DD3-8DED-AD15E62F4213}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove<br>"{746D6C7A-B5F8-4D20-82D8-AFAB8EBB1C69}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove<br>"{CFAE4B4B-A39A-48AF-828A-8DBDE3F0495B}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote<br>"{6609C431-01D5-4346-8382-98D74F3F633B}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]<br>"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|<br><br>R2 DUMeterSvc;DU Meter Service;C:\Program Files\DU Meter\DUMeterSvc.exe [2007-10-15 15:19]<br>R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]<br>\shell\AutoRun\command - E:\SETUP.EXE<br>\shell\configure\command - E:\SETUP.EXE<br>\shell\install\command - E:\SETUP.EXE<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2008-05-30 15:14:50 C:\Windows\Tasks\MalwareRemovalBot Scheduled Scan.job"<br>- C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.ex<br>- C:\Program Files\MalwareRemovalBot<br>.<br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-05-30 12:09:35<br>Windows 6.0.6000  NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Windows\System32\audiodg.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Windows\System32\WUDFHost.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-05-30 12:12:19 - machine was rebooted [Bry4n]<br>ComboFix-quarantined-files.txt  2008-05-30 17:12:12<br><br>Pre-Run: 83,671,408,640 bytes free<br>Post-Run: 83,721,551,872 bytes free<br><br>270&#9;--- E O F ---&#9;2008-05-30 21:13:36<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20567380</guid>
<pubDate>Sat, 31 May 2008 01:14:29 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20567336</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Combofix will reboot your computer. That is to be expected.<br><br>Delete Combofix.exe from your Desktop.<br>Download it again.<br><br>This time you will not use a CFScript file.  Just double click Combofix.exe and let it run.<br><br>Post back the contents of C:\Combofix.txt when it reboots and then finishes.<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20567336</guid>
<pubDate>Sat, 31 May 2008 00:59:21 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20567296</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : On second thinking the Combofix said something about not being able to run the program?<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20567296</guid>
<pubDate>Sat, 31 May 2008 00:46:18 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20567258</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : here are the logs.. I dont think Combofix worked correctly, my pc rebooted while doing this..<br><br>Malwarebytes' Anti-Malware 1.14<br>Database version: 807<br><br>11:16:00 PM 5/30/2008<br>mbam-log-5-30-2008 (23-16-00).txt<br><br>Scan type: Full Scan (C:\|J:\|)<br>Objects scanned: 137114<br>Time elapsed: 2 hour(s), 21 minute(s), 43 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 2<br>Registry Keys Infected: 10<br>Registry Values Infected: 3<br>Registry Data Items Infected: 1<br>Folders Infected: 0<br>Files Infected: 9<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>C:\Windows\System32\ssqPhffe.dll (Trojan.Vundo) -> Unloaded module successfully.<br>C:\Windows\System32\urQKcCvw.dll (Trojan.Vundo) -> Unloaded module successfully.<br><br>Registry Keys Infected:<br>HKEY_CLASSES_ROOT\CLSID\{38a6ce15-d55d-429c-a2a3-6a2d5198efdc} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CLASSES_ROOT\CLSID\{8bf46375-ada7-45e8-b948-c2deb8dea5ba} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8bf46375-ada7-45e8-b948-c2deb8dea5ba} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{f53bafe5-ce7a-4e95-95ac-a3912efd3739} (Trojan.Vundo) -> Delete on reboot.<br>HKEY_CLASSES_ROOT\CLSID\{0cf5d165-517e-48b6-b3c7-3054a24f8bf6} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{f53bafe5-ce7a-4e95-95ac-a3912efd3739} (Trojan.Vundo) -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{0cf5d165-517e-48b6-b3c7-3054a24f8bf6} (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqphffe  -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>C:\Windows\System32\ssqPhffe.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\Windows\System32\urQKcCvw.dll (Trojan.Vundo) -> Delete on reboot.<br>C:\Program Files\Trend Micro\HijackThis\backups\backup-20080530-202822-173.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1EY0JTRI\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NFJSP2DF\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Users\Bry4n\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XZ7NG8GF\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\jkkJdBsp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\pmNgHXRl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br>C:\Windows\System32\qoMcyWnl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.<br><br>ComboFix 08-05-29.1 - Bry4n 2008-05-30 23:26:54.1 - NTFSx86<br>Microsoft&reg; Windows Vista&#153; Home Premium   6.0.6000.0.1252.1.1033.18.1260 [GMT -5:00]<br>Running from: C:\Users\Bry4n\Desktop\ComboFix.exe<br>Command switches used :: C:\Users\Bry4n\Desktop\CFscript.txt<br> * Created a new restore point<br>.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 23:33, on 2008-05-30<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\WinTidy\WinTidy.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Windows\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll<br>O2 - BHO: (no name) - {2b7a6b19-a1d8-4366-8ae7-5157893bb823} - (no file)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {C1349062-D1A1-40DB-83CD-68CADE84FC37} - (no file)<br>O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"<br>O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"<br>O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKLM\..\Run: [MSServer] "rundll32.exe" C:\Windows\system32\yayaXOFY.dll,#1<br>O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe<br>O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe<br>O4 - Global Startup: hpzrcv01.LNK = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br>O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe<br><br>--<br>End of file - 9037 bytes<br><small>--<br>Uh-huh, and let me know when Elvis gets here.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20567258</guid>
<pubDate>Sat, 31 May 2008 00:36:09 EDT</pubDate>
</item>

<item>
<title>Re: [Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20566347</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Use the Add or Remove Installed Programs option to uninstall any entry resembling "MalwareBot".  You may not see it.<br><br>Please download<b>  <i>ATF Cleaner</i></b>  &raquo;<A HREF="http://www.atribune.org/ccount/click.php?id=1" >www.atribune.org/ccount/click.php?id=1</A><br>It does not require any installation.. It is set up to clean Windows 2k, XP & Vista TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><b>For all browsers:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows Vista to show hidden files:</b><br>To enable the viewing of Hidden files follow these steps: <br>&#8226;Close all programs so that you are at your desktop. <br>&#8226;Open the Control Panel menu and click <b>Folder Options</b>. <br>&#8226;After the new window appears select the <b>View</b> tab. <br>&#8226;Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226;Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226;Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226;Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226;Press the Apply button and then the OK button and exit My Computer. <br>&#8226;Now your computer is configured to show all hidden files. <b><u>Malware Removal Steps</u></b><br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: {328bb398-7515-7ea8-6634-8d1a91b6a7b2} - {2b7a6b19-a1d8-4366-8ae7-5157893bb823} - C:\Windows\system32\sfkwipus.dll<br>O2 - BHO: (no name) - {8BF46375-ADA7-45E8-B948-C2DEB8DEA5BA} - C:\Windows\system32\ssqPhffe.dll<br>O2 - BHO: (no name) - {C1349062-D1A1-40DB-83CD-68CADE84FC37} - C:\Windows\system32\vTLcCvTk.dll (file missing)<br>O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\urQKcCvw.dll,#1<br>O4 - HKCU\..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>&#8226; On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is <b>Un-</b>selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.<br><br>&#8226; Now click <b>Show Results</b>.  <u>Make sure all entries have a checkmark</u> at their far left.  <br>&#8226; You should now click on the <b>Remove Selected</b> button to remove all the listed malware. <br><br>MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>3. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>KILLALL::&#012; &#012;Driver::&#012;VundoFixSvc&#012; &#012;File::&#012;C:\Windows\system32\sfkwipus.dll&#012;C:\Windows\system32\ssqPhffe.dll&#012;C:\Windows\system32\urQKcCvw.dll&#012; &#012;Folder::&#012;C:\Program Files\MalwareRemovalBot&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad. Check that it includes all the entries from the Code Box.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; Your <b>MBAM log results;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20566347</guid>
<pubDate>Fri, 30 May 2008 21:16:51 EDT</pubDate>
</item>

<item>
<title>[Vundo] Ran all spyware software.. still have Vundo..</title>
<link>http://www.dslreports.com/forum/remark,20566030</link>
<description><![CDATA[<A HREF="/useremail/u/290394"><b>Ap4mvp</b></A> : Hi all I ran all the spyware progs listed on the site and even ran vundofix.. The virus keeps coming back.. Here is my HJT..<br><br>Any help is appreciated..<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 7:21:03 PM, on 5/30/2008<br>Platform: Windows Vista  (WinNT 6.00.1904)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16643)<br>Boot mode: Normal<br><br>Running processes:<br>C:\Windows\System32\smss.exe<br>C:\Windows\system32\csrss.exe<br>C:\Windows\system32\wininit.exe<br>C:\Windows\system32\csrss.exe<br>C:\Windows\system32\services.exe<br>C:\Windows\system32\lsass.exe<br>C:\Windows\system32\lsm.exe<br>C:\Windows\system32\winlogon.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\SLsvc.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\System32\ZoneLabs\vsmon.exe<br>C:\Windows\system32\Dwm.exe<br>C:\Windows\Explorer.EXE<br>C:\Windows\System32\ZoneLabs\avsys\ScanningProcess.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Windows\System32\spoolsv.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\system32\svchost.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\DU Meter\DUMeterSvc.exe<br>C:\Windows\system32\svchost.exe<br>C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>C:\Program Files\Spyware Doctor\pctsSvc.exe<br>C:\Windows\system32\svchost.exe<br>C:\Windows\System32\svchost.exe<br>C:\Windows\system32\SearchIndexer.exe<br>C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>C:\Program Files\Spyware Doctor\pctsTray.exe<br>C:\Windows\system32\WUDFHost.exe<br>C:\Windows\system32\taskeng.exe<br>C:\Windows\System32\mobsync.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\Program Files\Google\Gmail Notifier\gnotify.exe<br>C:\Windows\System32\ZoneLabs\avsys\ScanningProcess.exe<br>C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe<br>C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe<br>C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\DU Meter\DUMeter.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe<br>C:\Program Files\WinTidy\WinTidy.exe<br>C:\Program Files\Mozilla Firefox\firefox.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Windows\system32\wbem\wmiprvse.exe<br>C:\Windows\system32\SearchProtocolHost.exe<br>C:\Windows\system32\SearchFilterHost.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Windows\system32\wbem\wmiprvse.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br>O1 - Hosts: ::1 localhost<br>O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll<br>O2 - BHO: {328bb398-7515-7ea8-6634-8d1a91b6a7b2} - {2b7a6b19-a1d8-4366-8ae7-5157893bb823} - C:\Windows\system32\sfkwipus.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {8BF46375-ADA7-45E8-B948-C2DEB8DEA5BA} - C:\Windows\system32\ssqPhffe.dll<br>O2 - BHO: (no name) - {C1349062-D1A1-40DB-83CD-68CADE84FC37} - C:\Windows\system32\vTLcCvTk.dll (file missing)<br>O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"<br>O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"<br>O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"<br>O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"<br>O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\urQKcCvw.dll,#1<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"<br>O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"<br>O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe<br>O4 - HKCU\..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe<br>O4 - Startup: WinTidy.lnk = C:\Program Files\WinTidy\WinTidy.exe<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll<br>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll<br>O13 - Gopher Prefix: <br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/OnlineScanner.cab" >www.eset.eu/OnlineScanner.cab</A><br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL<br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe<br>O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe<br>O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe<br>O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe<br>O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe<br>O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe<br>O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe<br><br>--<br>End of file - 11117 bytes<br><br>HJT Log file now V2.0.2]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20566030</guid>
<pubDate>Fri, 30 May 2008 20:10:00 EDT</pubDate>
</item>

</channel>
</rss>
